PVV Overijssel
€7,500
Insufficient fulfilment of data breach notification obligations
Decision Date
16 de junho de 2020
Authority
Dutch Supervisory Authority for Data Protection (AP)
NL
Sector
Public Sector and Education
Country
NL
Law
GDPRStatus
FINALDescription
The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email regarding the convening of a meeting had been sent via an open distribution list due to a human error. Since the total of 101 recipients were addressed as 'Friends of the PVV' in the email, the political beliefs of the data subjects were thus disclosed to all addressees.
Legal Citations
Art. 33
Issues & Violations
Insufficient fulfilment of data breach notification obligations